The AI Governance Glossary
Artificial intelligence introduces a growing collection of technical, governance, compliance and assurance terminology. This glossary explains those terms in practical language for accounting firms, AIGAS Certified Service Providers, software vendors and other organisations working with AI — and defines the terminology used specifically within the AIGAS™ AI Governance Assurance Standard.
The pathway in ten terms.
Before diving into the full A–Z list, here is the core AIGAS vocabulary that ties everything together — from first visibility through to independently validated assurance.
Understand what AI is being used.
Understand how ready your organisation is.
Establish and evidence the foundations of AI governance.
Demonstrate more structured governance with independent validation.
The international AI management-system standard sitting beyond the AIGAS pathway.
An AIGAS Certified Service Provider capable of supporting firms through the AIGAS framework.
Basic public vendor information has been established.
The vendor has completed and signed the AIGAS transparency disclosure.
Vendor disclosures and supporting evidence have been reviewed.
A future formal AIGAS vendor-certification level.
Common acronyms.
The abbreviations that come up most often across AIGAS documentation, assessments and vendor disclosures.
Acceptable Use
-
The rules defining how employees and other authorised users may and may not use AI within an organisation.
Acceptable-use requirements may cover which AI tools are permitted, what information can be entered into them, when human review is required and which activities are prohibited.
See also: AI Policy, Approved AI Tool, Prohibited Use.
Accreditation
-
Formal recognition that an organisation is competent to perform a particular conformity-assessment activity.
Accreditation should not be confused with certification. AIGAS is an independent governance and assurance standard. AIGAS certification does not mean that a firm has been accredited by UKAS, ISO or a professional accounting body unless this is expressly stated.
Agentic AI
-
AI designed to undertake a sequence of actions towards an objective, often with a degree of autonomy.
Unlike a conventional chatbot that simply responds to individual prompts, an agentic system may plan tasks, access systems, call other software, retrieve information and take actions.
Greater autonomy normally requires stronger governance because the system may be capable of acting rather than simply advising.
See also: AI Agent, Human Oversight.
AI
-
Artificial Intelligence.
A broad term for computer systems capable of performing tasks normally associated with aspects of human intelligence, such as understanding language, recognising patterns, generating content, making predictions or supporting decisions.
For governance purposes, organisations should consider both obvious AI products and AI functionality embedded within existing software.
AI Agent
-
An AI-enabled system capable of performing tasks or taking a sequence of actions on behalf of a user or organisation.
An AI agent might research information, prepare documents, update systems, call APIs or trigger workflows. The extent of permissions given to an agent is an important governance consideration.
AI Assurance
-
The process of obtaining confidence that AI is being used, managed or controlled in accordance with defined requirements.
Assurance may consider governance, risk, data protection, security, human oversight, documentation, monitoring and evidence.
AI Governance
-
The structures, policies, responsibilities, processes and controls used to direct and oversee how AI is selected, developed, deployed and used.
Good AI governance is not intended simply to restrict AI. Its purpose is to enable organisations to use AI deliberately, responsibly and with appropriate oversight.
AI Governance Lead
-
The person assigned responsibility for coordinating or overseeing AI governance within an organisation.
This does not necessarily need to be a dedicated job. In a smaller accounting firm the responsibility may sit with a partner, director, compliance lead, IT lead or another appropriately senior individual.
AI Governance Maturity
-
A description of how developed an organisation's AI governance arrangements are.
An organisation may move from informal AI use, through basic controls and documented governance, towards more structured management, monitoring and assurance.
AIGAS Bronze and Silver represent different levels of governance maturity.
AI Incident
-
An event involving AI that causes, or could cause, harm, error, inappropriate disclosure, compliance failure, service disruption or another material problem.
Examples could include confidential information being entered into an inappropriate AI service, materially incorrect AI-generated advice being issued to a client or an AI-enabled process behaving unexpectedly.
AI Literacy
-
The knowledge and understanding needed to use and oversee AI appropriately.
For staff this may include understanding AI's capabilities, limitations, confidentiality risks, hallucinations, appropriate prompting, verification requirements and the organisation's own AI policies.
AI Model
-
The computational model underlying an AI system.
Examples include language models used to generate text, vision models used to analyse images and models used for prediction or classification.
A software vendor may build its own model or incorporate models supplied by third parties.
AI Output
-
Information produced by an AI system.
This may include text, calculations, classifications, recommendations, images, summaries, code or other generated material.
AI output should not automatically be assumed to be correct simply because it appears confident or authoritative.
AI Policy
-
An organisation's documented rules and principles governing the use of AI.
An AI policy commonly addresses approved tools, prohibited activities, confidential information, human oversight, accountability, acceptable use and incident reporting.
A policy is an important governance control, but a policy alone is not AI governance.
AI Risk Assessment
-
A structured assessment of the risks associated with an AI system, tool or use case.
It may consider factors including confidentiality, data protection, accuracy, professional reliance, cyber security, vendor risk, bias, regulatory consequences and the potential impact if the AI produces an incorrect result.
AI Strategy
-
An organisation's intended approach to adopting and using AI.
A strategy should help explain where AI can create value, which activities are appropriate for AI, the organisation's priorities and how adoption will be governed.
AI System
-
Software or a combination of technologies that uses AI to produce outputs, predictions, recommendations, content or actions.
For AIGAS purposes, governance should consider both standalone AI services and AI functionality contained within wider business applications.
AI Tool
-
A software product, feature or service that uses artificial intelligence.
An AI tool may be a standalone service such as a generative AI assistant or an AI capability embedded within accounting, tax, payroll, productivity or other business software.
AI Tool Owner
-
The person within an organisation responsible for the governance or business ownership of a particular AI tool.
Ownership does not necessarily mean technical ownership. The owner should be able to explain why the tool is used, by whom and under what controls.
AI Tool Register
-
A structured, living inventory of the AI tools and AI-enabled systems being used within an organisation.
The AIGAS AI Tool Register is the starting point of the AIGAS pathway because an organisation cannot effectively govern AI that it does not know is being used.
A register may record the tool, its purpose, ownership, use cases, relevant data and governance status.
It should be maintained as AI use changes rather than completed once and forgotten.
AI Use Case
-
A defined way in which an AI system is being used.
For example, the same AI product might have one use case for drafting internal emails and another for reviewing client tax documentation. Those uses may carry very different risks even though the underlying tool is the same.
AI Vendor
-
An organisation providing software or services containing AI functionality.
Within AIGAS, vendors may participate in the AIGAS Vendor Programme to provide greater transparency about how their AI features operate and are governed.
AIGAS Advisory Board
-
The independent group of advisers helping to guide the development and evolution of the AIGAS Standard.
Its role includes helping ensure that the Standard remains practical, proportionate and relevant to developments in accounting, AI, technology, cyber security, risk and governance.
AIGAS Assurance
-
Demonstration that an organisation has implemented the governance controls required by the relevant level of the AIGAS Standard.
AIGAS assurance is based on evidence rather than unsupported declarations.
See also: Bronze, Silver, Evidence-Based Assurance.
AIGAS Assurance Pathway
-
The progressive route through AIGAS governance:
AI Tool Register → Bronze → Silver → ISO/IEC 42001 pathway
Organisations do not need to begin with a complex management system. The pathway starts with visibility and progressively introduces stronger governance and assurance.
AIGAS Bronze
-
The foundational AIGAS assurance level.
Bronze is designed to demonstrate that an organisation understands where AI is being used and has established proportionate foundational controls around areas such as ownership, acceptable use, confidentiality, risk, human oversight and staff awareness.
Bronze is evidence-based but designed to remain accessible to smaller organisations and those at an earlier stage of AI adoption.
See also: Silver, AI Tool Register.
AIGAS Certified Firm
-
An organisation that holds a current AIGAS certification or assurance status at the applicable AIGAS level.
Certification relates to conformity with the relevant AIGAS requirements and should not be represented as regulatory approval or ISO/UKAS accreditation.
AIGAS Certified Service Provider
-
See CSP — Certified Service Provider.
AIGAS Directory
-
The AIGAS public directory used to identify participants within the AIGAS ecosystem, including certified firms, Certified Service Providers and relevant vendor listings.
The status displayed should be interpreted according to the specific programme concerned.
For example, a Verified Vendor has a different meaning from an AIGAS Silver firm.
AIGAS Governance Domains
-
The principal areas into which AIGAS governance requirements are organised.
These cover the key components needed to move from informal AI adoption towards structured governance, including strategy and purpose, risk and compliance, data protection and confidentiality, governance and accountability, operational controls, and people or ongoing governance activities.
AIGAS Platform
-
The online environment used to access AIGAS tools and governance processes.
Depending on the user's role and services being used, this can include the AI Tool Register, Self-Assessment, Bronze and Silver activities, evidence submission, training and related governance records.
AIGAS Self-Assessment
-
A free, informal AI governance readiness assessment available through the AIGAS platform.
It provides an indication of an organisation's current governance position and highlights possible strengths, gaps and next steps.
The Self-Assessment is not a certification assessment. It does not require evidence uploads and completing it does not award Bronze or Silver.
See also: Readiness Assessment, Bronze Assessment.
AIGAS Silver
-
The more advanced AIGAS assurance level.
Silver builds on the foundations established through Bronze and looks for evidence that AI governance is structured, documented, embedded into operational practice and actively monitored.
Silver includes independent assessment rather than relying solely on the organisation's own declaration.
AIGAS™
-
AI Governance Assurance Standard.
A practical, sector-specific AI governance standard designed initially for UK accounting firms.
AIGAS helps organisations identify their use of AI, introduce proportionate governance controls, evidence those controls and progressively strengthen their governance as AI adoption develops.
AIGAS operates a pathway encompassing the AI Tool Register, Bronze and Silver, with ISO/IEC 42001 sitting beyond the AIGAS pathway.
Annual Revalidation
-
The process used to ensure that an organisation's AIGAS governance position remains current rather than relying indefinitely on evidence from an earlier assessment.
API
-
Application Programming Interface.
A mechanism that allows one software system to communicate with another.
AI models are frequently accessed through APIs, allowing vendors to embed third-party AI capabilities inside their own applications.
Approved AI Tool
-
An AI tool that an organisation has reviewed and authorised for defined purposes.
Approval should not necessarily mean that every possible use of the tool is permitted. Conditions may apply concerning data, users, functionality or particular use cases.
Assessment
-
A structured examination of whether defined requirements have been met.
Within AIGAS the meaning depends on context. The free AIGAS Self-Assessment is an informal readiness exercise, while formal Bronze or Silver activities relate to demonstrating conformity with the AIGAS Standard.
Audit Trail
-
A record showing what actions, decisions or changes have taken place and, where appropriate, who performed them and when.
Audit trails can be important evidence that governance controls are operating in practice.
Bias
-
Systematic tendencies in an AI system that can lead to unfair, distorted or inappropriate outcomes.
Bias can arise from training data, system design, prompts, deployment context or the way outputs are interpreted.
Bronze
-
Short for AIGAS Bronze, the foundational AIGAS assurance level. It demonstrates that an organisation understands where AI is being used and has established proportionate foundational controls around ownership, acceptable use, confidentiality, risk, human oversight and staff awareness.
See also: AIGAS Silver, AI Tool Register.
Bronze Assessment
-
The formal process through which an organisation demonstrates that the requirements applicable to AIGAS Bronze have been implemented.
This should not be confused with the free AIGAS Self-Assessment, which is an informal readiness check.
Certification
-
Formal confirmation that specified requirements have been satisfied.
Within AIGAS, certification refers to meeting the requirements of the relevant AIGAS programme or level.
It does not, by itself, constitute regulatory approval or accreditation by UKAS, ISO or a professional accounting body.
Certified Service Provider — CSP
-
An individual or organisation certified by AIGAS to support firms implementing and maintaining the AIGAS Standard.
CSPs are expected to understand both the AIGAS framework and the practical environment in which accounting firms operate.
They can support implementation, but certification and assurance processes must maintain appropriate independence and governance.
Change Control
-
A structured process for identifying, reviewing and recording changes.
In AI governance this can include changes to AI tools, models, configurations, vendors, permitted use cases, data processing arrangements or governance controls.
Client Confidentiality
-
The obligation to protect information entrusted to an accounting or professional services firm by its clients.
The use of AI does not remove existing professional confidentiality obligations.
Firms should therefore understand what information is submitted to AI systems, where it goes, who processes it and whether the intended use is appropriate.
Code of Conduct
-
A set of behavioural and professional requirements applying to participants in a programme.
AIGAS Certified Service Providers are subject to an AIGAS Code of Conduct as part of maintaining provider certification.
Competent Individual
-
A person with sufficient knowledge, skills or experience to undertake a particular review or decision.
For AI-assisted professional work, the appropriate reviewer should be capable of identifying significant errors rather than merely confirming that an AI output looks plausible.
Compliance
-
Conformity with applicable laws, regulations, professional obligations, contractual requirements, standards and internal policies.
AI governance helps organisations identify where AI use intersects with these existing obligations.
Control
-
A measure designed to manage a risk or achieve a governance objective.
Controls may be technical, organisational, procedural or human.
Examples include restricting confidential data, requiring human review, maintaining an AI Tool Register or requiring approval before adopting a new AI tool.
Control Evidence
-
Evidence specifically demonstrating that a governance control exists and is operating.
For example, an AI policy may show that a rule exists, while training records, approvals or operational records may demonstrate that the rule is actually being applied.
Corrective Action
-
An action taken to address a problem or non-conformity and, where appropriate, prevent it from recurring.
Corrective actions are an important part of continual improvement.
CSP
-
Short for Certified Service Provider: an individual or organisation certified by AIGAS to support firms implementing and maintaining the AIGAS Standard. CSPs are expected to understand both the AIGAS framework and the practical environment in which accounting firms operate.
CSP Fast Track
-
An AIGAS CSP route for applicants who already hold recognised ISO/IEC 42001 Lead Implementer or Lead Auditor qualifications.
The route recognises relevant prior learning while retaining AIGAS-specific requirements such as familiarisation with the AIGAS framework, practical assessment and the Code of Conduct.
CSP ID
-
The identifier assigned to an AIGAS Certified Service Provider.
It provides a consistent way of identifying a provider within the AIGAS ecosystem and supporting verification of their status.
CSP Standard Track
-
The normal AIGAS provider-certification pathway for suitably qualified professionals who do not enter through the ISO/IEC 42001 Fast Track.
It includes AIGAS framework training, knowledge assessment and practical evaluation.
Cyber Essentials
-
A UK cyber security certification scheme focused on fundamental technical controls.
Cyber Essentials relates primarily to cyber security rather than AI governance, although cyber security credentials may form part of vendor or supplier due diligence.
Data Controller
-
An organisation or person that determines the purposes and means of processing personal data.
Whether an accounting firm, software vendor or other party acts as controller or processor depends on the particular processing activity involved.
Data Minimisation
-
The principle of using only the personal data that is necessary for a defined purpose.
In AI governance, organisations should consider whether information submitted to an AI system is genuinely required or whether less data could be used.
Data Processing Agreement — DPA
-
An agreement setting out how personal data will be processed between relevant parties.
DPAs are particularly important when software providers process personal data on behalf of customers.
They can provide useful governance evidence when assessing AI vendors.
Data Processor
-
An organisation or person processing personal data on behalf of a controller.
AI and cloud service supply chains may involve several processors and subprocessors.
Data Protection Impact Assessment — DPIA
-
A structured assessment used to identify and manage data-protection risks associated with processing personal data.
A DPIA may be necessary where AI processing is likely to create a high risk to individuals' rights and freedoms.
Data Residency
-
The geographical location in which data is stored or processed.
For AI services this may include prompt data, uploaded documents, generated outputs, logs and backups.
Data Retention
-
The period for which information is stored.
Organisations assessing AI providers should understand how long prompts, files, outputs and associated logs are retained and whether those periods can be controlled.
Delta Briefing
-
AIGAS-specific training provided to eligible CSP Fast Track applicants.
Rather than repeating knowledge already demonstrated through recognised ISO/IEC 42001 qualifications, the briefing focuses on the differences between that existing knowledge and the AIGAS framework, sector context and platform.
Disclosure
-
Information made available about an AI system, product, governance arrangement or risk.
Within the AIGAS Vendor Programme, vendor disclosures are intended to help accounting firms understand relevant characteristics of AI-enabled products.
DPA
-
Short for Data Processing Agreement: an agreement setting out how personal data will be processed between relevant parties. DPAs are particularly important when software providers process personal data on behalf of customers, and can provide useful governance evidence when assessing AI vendors.
DPIA
-
Short for Data Protection Impact Assessment, a structured assessment used to identify and manage data-protection risks associated with processing personal data. A DPIA may be necessary where AI processing is likely to create a high risk to individuals’ rights and freedoms.
Due Diligence
-
The process of investigating and evaluating an organisation, system or supplier before relying upon it.
AI vendor due diligence may include data protection, security, AI functionality, subcontractors, data usage, model providers, contractual arrangements and incident-response capabilities.
Embedded AI
-
AI functionality incorporated within a wider software product rather than offered as an obvious standalone AI service.
Examples can include AI features inside accounting software, productivity suites, CRM systems or tax applications.
Embedded AI is particularly important from a governance perspective because staff may be using AI without consciously thinking of the underlying software as an “AI tool”.
Evidence
-
Information demonstrating that a governance requirement or control is actually in place.
Evidence may include policies, registers, records, approvals, training records, risk assessments, screenshots, logs, documented reviews or other appropriate material.
The purpose of evidence is to demonstrate implementation — not to create paperwork simply for its own sake.
Evidence-Based Assurance
-
Assurance supported by evidence showing that required governance controls have actually been implemented.
AIGAS uses an evidence-based approach because unsupported self-declaration alone does not demonstrate effective governance.
Explainability
-
The extent to which the operation or result of an AI system can be understood or explained.
The appropriate level of explainability depends on the nature of the system, the decision being supported and the consequences of relying on its output.
Fast Track
-
See CSP Fast Track.
Firm User
-
A user of the AIGAS platform acting on behalf of an accounting firm or other participating organisation.
Depending on permissions, Firm Users may maintain AI Tool Register entries, undertake assessments, provide evidence, complete training or manage governance activities.
Foundation Controls
-
The basic governance measures that establish control and visibility over AI use.
Within AIGAS these are particularly associated with the Bronze level.
Founding Vendor / Founding Participant
-
A vendor participating during the early development of the AIGAS Vendor Programme and helping provide practical industry input into the transparency framework.
Founding participation should not be interpreted as certification.
Framework Training
-
Training provided to CSP candidates on the AIGAS Standard, its requirements and its application within accounting firms.
Generative AI — GenAI
-
AI capable of generating new content such as text, images, audio, video, software code or other material.
Large Language Models such as those used in AI assistants are a common form of generative AI.
Governance
-
The structures and processes through which an organisation directs, oversees and remains accountable for an activity.
See AI Governance.
Governance Domain
-
A defined area within a governance framework used to group related controls and objectives.
AIGAS organises its requirements across six governance domains.
Governance Evidence
-
Documents, records or system information capable of demonstrating that AI governance controls are operating.
The emphasis should be on meaningful evidence rather than unnecessary documentation.
Guardrail
-
A restriction, rule or technical mechanism intended to reduce inappropriate AI behaviour or use.
Guardrails can exist within the AI system itself or within the organisation using it.
They do not replace human oversight or wider governance.
Hallucination
-
An AI-generated response that appears plausible but contains false, fabricated, unsupported or inaccurate information.
Hallucinations are particularly important in accounting and professional services because confidently presented errors can be mistaken for reliable information.
Human verification is therefore an important control where AI contributes to professional outputs.
Human Oversight
-
The broader principle that appropriate human responsibility and review should remain in place around AI.
Human oversight helps ensure that accountability does not simply transfer from a professional to a technology provider or AI model.
Human-in-the-Loop — HITL
-
An arrangement in which a human remains involved in reviewing, approving or intervening in an AI-enabled process.
The appropriate degree of human involvement depends on the risk and consequences of the task.
ICO
-
Information Commissioner's Office.
The UK's independent regulator responsible for information rights and data protection.
Its work is particularly relevant to AI where personal data is processed.
Incident Response
-
The documented process for identifying, managing, escalating, recording and learning from incidents.
An AI incident-response process should explain what happens when AI creates or contributes to a significant error, data issue, security problem or governance failure.
Independent Assessment
-
An assessment performed by a party with appropriate separation from the activity being assessed.
AIGAS Silver introduces independent validation as part of providing stronger assurance than the foundational Bronze level.
Independent Assessor
-
A person authorised to review evidence or conduct an assessment with the appropriate degree of independence from the implementation work being examined.
ISO
-
International Organization for Standardization.
An international organisation that develops standards across a wide range of industries and disciplines.
AIGAS is independent of ISO.
ISO/IEC 27001
-
An international standard for information security management systems.
ISO/IEC 27001 primarily addresses information security rather than AI governance, although many of its management-system and security principles can complement AI governance.
ISO/IEC 42001
-
An international standard for Artificial Intelligence Management Systems.
It provides requirements for establishing, implementing, maintaining and continually improving a structured AI management system.
AIGAS is designed as a proportionate sector-specific governance pathway which can help organisations develop the structures and evidence needed before considering the broader requirements of ISO/IEC 42001.
Knowledge Exam
-
An assessment forming part of the standard pathway for AIGAS Certified Service Providers.
It assesses understanding of the AIGAS framework and its practical application.
Eligible ISO/IEC 42001-qualified applicants entering through the CSP Fast Track may be exempt from the AIGAS Knowledge Exam while still completing AIGAS-specific requirements.
Large Language Model — LLM
-
A type of AI model trained to process and generate language.
LLMs underpin many generative AI assistants and can perform tasks such as drafting, summarising, translation, analysis, question answering and code generation.
LLMs generate responses probabilistically and should not be treated as inherently authoritative sources of fact.
Listed Vendor
-
AIGAS Vendor Programme Level 1.
A vendor for which AIGAS publishes a basic profile using publicly available information and confirms basic identity, product category and website details.
Being Listed should not be interpreted as an endorsement or as confirmation that the vendor's AI governance has been independently assessed.
Model
-
See AI Model.
Model Provider
-
The organisation providing the underlying AI model used within an application.
A software vendor and model provider may be different organisations. For example, a software company may integrate another organisation's language model through an API.
Understanding this supply chain is an important part of vendor transparency.
Monitoring
-
Ongoing observation of AI systems, controls, incidents, usage or risks to determine whether governance continues to operate effectively.
AI governance requires ongoing monitoring because AI systems, vendors, functionality and organisational usage can change rapidly.
NCSC
-
National Cyber Security Centre.
The UK's national technical authority for cyber security.
NCSC guidance can be relevant to the security aspects of AI adoption and supplier management.
Non-Conformity
-
A failure to satisfy a defined requirement.
Where a non-conformity is identified, an organisation may need to undertake corrective action before assurance can be confirmed or maintained.
Ongoing Review
-
The process of periodically reviewing AI tools, risks, controls and governance arrangements.
AI governance should not be treated as a one-off project because software functionality, vendors, risks and organisational usage evolve.
Output Validation
-
The process of checking whether an AI-generated result is sufficiently accurate, appropriate and reliable for its intended purpose.
The level of validation should reflect the potential consequences of an error.
Ownership
-
Clearly assigning responsibility for an AI tool, control, risk or governance activity.
Defined ownership is central to accountability: a governance process is weaker when responsibility is assumed rather than explicitly assigned.
Personal Data
-
Information relating to an identified or identifiable living individual.
The use of personal data within AI systems can create obligations under data-protection law and should form part of an organisation's AI risk assessment.
Personally Identifiable Information — PII
-
A commonly used term for information capable of identifying an individual.
In a UK data-protection context, personal data is generally the more appropriate legal terminology.
Practical Assessment
-
An assessment designed to determine whether a CSP candidate can apply AIGAS principles to practical situations rather than simply recall theoretical knowledge.
Privacy
-
The appropriate protection and handling of information relating to individuals.
AI governance and privacy overlap significantly where AI tools process personal data.
Professional Judgement
-
Judgement exercised by an appropriately qualified or experienced professional when applying their knowledge to a particular situation.
AI can support professional judgement but does not automatically replace the professional's responsibility for the resulting work.
Prohibited AI Use
-
An activity that an organisation has determined AI must not be used for.
Prohibitions may relate to particular data, decisions, systems, clients, tasks or levels of autonomy.
Prompt
-
An instruction or information provided to a generative AI system to influence the output it produces.
A prompt can contain confidential, personal or commercially sensitive information, making appropriate prompt usage an AI governance issue.
Prompt Injection
-
An attack or manipulation technique in which instructions are introduced into information processed by an AI system in an attempt to influence or override its intended behaviour.
Prompt injection is particularly relevant where AI systems can access documents, external information, tools or automated actions.
Proportionality
-
The principle that governance controls should reflect the scale, context and risk of the AI being governed.
A low-risk internal drafting tool does not necessarily require the same controls as an AI system materially influencing client advice or making automated decisions.
Proportionality is a core principle behind the AIGAS approach.
Readiness Assessment
-
Another description for the informal AIGAS Self-Assessment.
It helps an organisation understand its current AI governance position before deciding whether to pursue formal AIGAS assurance.
Readiness Score
-
The indicative result generated by the AIGAS Self-Assessment.
It is intended to help organisations identify strengths, gaps and next steps.
It is not an AIGAS certification score and does not award Bronze or Silver status.
Recertification
-
The process by which a certification is reassessed or renewed after a defined period.
For example, AIGAS CSP certification is subject to periodic renewal requirements.
Responsible AI
-
The design, development and use of AI in a manner that appropriately considers accountability, safety, privacy, fairness, transparency, security and human responsibility.
Responsible AI is broader than simply complying with individual legal requirements.
Responsible Use
-
Using AI for legitimate purposes while applying appropriate human judgement, confidentiality, risk management, accountability and governance controls.
Revalidation
-
Confirmation that previously demonstrated governance remains current and effective.
AIGAS firm assurance is not intended to be a one-time exercise: changes to tools, risks, staff and working practices mean governance needs to be reviewed over time.
Risk
-
The possibility that an event or activity may lead to an unwanted outcome.
AI risks can include inaccurate outputs, confidentiality breaches, inappropriate reliance, bias, regulatory issues, cyber threats, operational failures and reputational harm.
Risk Appetite
-
The level and type of risk an organisation is prepared to accept in pursuit of its objectives.
Risk appetite can help determine which AI use cases require stronger controls or should not be permitted.
Risk Owner
-
The person responsible for overseeing and managing a particular risk.
Risk Register
-
A structured record of identified risks, their significance, ownership, controls and treatment.
An AI-specific risk register may exist separately or AI risks may be incorporated into the organisation's wider risk-management framework.
SaaS
-
Software as a Service.
Software delivered remotely, typically through a browser or application and usually hosted by the supplier.
Many AI tools and accounting platforms are delivered using the SaaS model.
Self-Assessment
-
Short for AIGAS Self-Assessment, a free, informal AI governance readiness assessment available through the AIGAS platform. It indicates an organisation’s current governance position and highlights possible strengths, gaps and next steps.
Within AIGAS terminology, care should be taken not to confuse the free readiness Self-Assessment with formal assessment or certification activities: it does not require evidence uploads and completing it does not award Bronze or Silver.
Self-Certification
-
A certification approach in which the organisation evaluates itself against defined requirements and formally declares conformity, normally while retaining evidence demonstrating that those requirements have been met.
Within AIGAS, Bronze uses a self-assessment/self-certification approach supported by evidence, while Silver adds independent assessment.
Self-Declaration
-
A statement by an organisation that it complies with a requirement.
A declaration alone is weaker than evidence-based assurance. AIGAS expects relevant claims to be supported by evidence.
Service Provider
-
An organisation or consultant providing services to help firms establish or improve AI governance.
Only providers holding the relevant current AIGAS certification should describe themselves as an AIGAS Certified Service Provider.
Shadow AI
-
AI being used within an organisation without appropriate visibility, approval or governance.
Examples can include employees using personal AI accounts for work, unapproved browser tools or AI features being activated inside existing software without anyone formally reviewing them.
Shadow AI is one reason maintaining an AI Tool Register is important.
Silver
-
Short for AIGAS Silver, the more advanced AIGAS assurance level. It builds on the foundations established through Bronze and looks for evidence that AI governance is structured, documented, embedded into operational practice and actively monitored, including independent assessment rather than self-declaration alone.
See also: AIGAS Bronze.
Silver Assessment
-
The formal evaluation undertaken to determine whether an organisation satisfies the requirements for AIGAS Silver.
Silver requires a more structured and independently validated level of governance than Bronze.
SOC 2
-
A framework for reporting on controls operated by service organisations, commonly used by technology and cloud providers.
A SOC 2 report can provide useful supplier-assurance information but does not by itself demonstrate AI governance conformity.
Staff Awareness Training
-
Training intended to ensure that employees understand the organisation's rules, expectations and principal risks relating to AI.
Training should be relevant to what staff actually do rather than being treated purely as a certification exercise.
Standard Track
-
See CSP Standard Track.
Subprocessor
-
A further organisation used by a data processor to process personal data.
AI services may involve several layers of providers, including cloud infrastructure, AI model providers and specialist service providers.
Understanding subprocessors can therefore be an important part of vendor due diligence.
Supplier Governance
-
The controls used to select, assess, approve and monitor suppliers.
For AI systems this should consider not just the immediate vendor but, where relevant, the wider chain of model providers, hosting providers and subprocessors.
Third-Party AI
-
AI technology provided or operated by an organisation outside the organisation using it.
Third-party AI creates additional governance considerations because the user organisation may have limited visibility or control over the underlying system.
Tool Approval
-
The process through which an organisation evaluates and formally approves an AI tool for specified uses.
Approval should normally consider the tool, vendor, data involved, intended use and associated risks.
Training Data
-
Information used to train or adapt an AI model.
This is distinct from information a customer enters into an AI system while using it.
Organisations evaluating vendors should understand whether customer information may be used for model training or improvement.
Transparency
-
Providing sufficient information for relevant parties to understand how AI is being used, governed or supplied.
Transparency does not necessarily require disclosure of proprietary technical information. It should provide the information reasonably needed to understand relevant risks and responsibilities.
Transparency Questionnaire
-
The structured AIGAS questionnaire used within the Vendor Programme to obtain information directly from software vendors about their AI capabilities and governance arrangements.
See also: Verified Vendor.
UK GDPR
-
The United Kingdom's data-protection framework derived from the General Data Protection Regulation and applicable UK legislation.
AI systems processing personal data must be considered within the organisation's existing data-protection obligations.
Use Case
-
See AI Use Case.
Validation
-
The process of determining whether something is suitable, accurate or operating as intended.
Within AI governance this can apply to AI outputs, controls, systems, evidence or governance claims.
Vendor
-
A company or organisation supplying software, technology or services.
Within the AIGAS ecosystem, the term commonly refers to software providers whose products are used by accounting firms and which may contain AI functionality.
Vendor Due Diligence
-
The process of evaluating a supplier before or during its use.
For AI-enabled products this may include understanding the vendor's AI functionality, model providers, information security, data protection, data residency, retention, training-data practices, incident processes and contractual controls.
Vendor Programme
-
The AIGAS framework intended to improve transparency around AI-enabled software supplied to accounting firms.
The programme allows different levels of disclosure and assessment rather than treating every vendor listing as a certification.
Vendor Transparency
-
The disclosure of information needed by customers to make informed decisions about an AI-enabled product.
Important areas can include AI functionality, model providers, customer-data usage, storage, retention, security, subprocessors, human oversight and incident management.
Vendor — Assessed
-
AIGAS Vendor Programme Level 3.
A status in which vendor disclosures have moved beyond self-reported transparency and supporting evidence has been examined by AIGAS.
Vendor — Certified
-
AIGAS Vendor Programme Level 4.
A future formal vendor-certification level within the AIGAS Vendor Programme.
This level is under development and should not be used to describe vendors unless and until the relevant certification programme is operational and the vendor has satisfied its requirements.
Vendor — Listed
-
See Listed Vendor.
Vendor — Verified
-
See Verified Vendor.
Verified Vendor
-
AIGAS Vendor Programme Level 2.
A vendor that has completed and signed off the AIGAS transparency questionnaire.
“Verified” means that the vendor has provided the required disclosure; it should not be interpreted as the same thing as an independently certified AI product.
Version Control
-
The process of identifying and managing different versions of documents, standards, policies, systems or other controlled information.
Version control is important in AI governance because requirements, policies, AI tools and underlying functionality can change.
No terms match your search. Try a different word, or browse the A–Z list above.
Terminology should make governance clearer, not more complicated.
AI terminology will continue to evolve as the technology, regulation and professional environment develop. AIGAS uses terminology to make governance clearer, not more complicated.
What AI are we using, why are we using it, what could go wrong, who is responsible, what controls do we have, and can we demonstrate that those controls actually work?
Understand where your firm stands today.
Once the language of AI governance makes sense, the next step is finding out how your own firm measures up against it.
